Add Comment

You are not currently logged in. If you do not have a user account then please consider creating one and logging in before you post your comment. This will allow you to track replies to your comment, and take part in the site much more freely.

To add your comment, fill in all the boxes below and then preview it to make sure you're happy with the way that it looks.

This is the comment you were replying to, attached to the article How To Migrate to a full encrypted LVM system:


Re: How To Migrate to a full encrypted LVM system
Posted by gpall (79.103.xx.xx) on Wed 20 Feb 2008 at 17:09
Of course, one should note the following scenario:

Your computer is shutdown. You leave home.
CIA sneaks in. They boot with a live-cd.
They mount your /boot partition, unpack
your initrd image, and they add some
(trivial) code, so that your passphrase
is written to the /boot partition, before
it is passed to cryptsetup. They pack back
the image, and replace the existing one.

You return from home, turn on your computer.
You are asked for the passphrase, you give it,
it is written to /boot, it is passed to cryptsetup,
and all works fine.

Next day, you leave home, CIA breaks in and
grabs your computer... Hasta la vista baby!

The solution is to boot from a boot partition
on some kind of usb drive which you always carry
on you.

Username:Anonymous
Title:
Your Comment:

Posting Format:

 

Inappropriate comments will be removed.

Some help on entry formatting is available

User Login

Username:

Password:

[ Advanced Login ]

Register Account

Quick Site Search